Thread (5 messages) 5 messages, 4 authors, 2016-06-15

Re: [PATCH] gitk: use mktemp -d to avoid predictable temporary directories

From: Pat Thoyts <hidden>
Date: 2016-06-15 23:01:37

David Aguilar [off-list ref] writes:
quoted hunk
gitk uses a predictable ".gitk-tmp.$PID" pattern when generating
a temporary directory.

Use "mktemp -d .gitk-tmp.XXXXXX" to harden gitk against someone
seeding /tmp with files matching the pid pattern.

Signed-off-by: David Aguilar <redacted>
---
This issue was brought up during the first review of the previous patch
back in 2009.

http://thread.gmane.org/gmane.comp.version-control.git/132609/focus=132748

This is really [PATCH 2/2] and should be applied on top of my previous
gitk patch.

gitk | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/gitk b/gitk
index 82293dd..dd2ff63 100755
--- a/gitk
+++ b/gitk
@@ -3502,7 +3502,8 @@ proc gitknewtmpdir {} {
	} else {
	    set tmpdir $gitdir
	}
-	set gitktmpdir [file join $tmpdir [format ".gitk-tmp.%s" [pid]]]
+	set gitktmpformat [file join $tmpdir ".gitk-tmp.XXXXXX"]
+	set gitktmpdir [exec mktemp -d $gitktmpformat]
	if {[catch {file mkdir $gitktmpdir} err]} {
	    error_popup "[mc "Error creating temporary directory %s:" $gitktmpdir] $err"
	    unset gitktmpdir
This is a problem on Windows where we will not have mktemp. In Tcl 8.6
the file command acquired a "file tempfile" command to help with this
kind of issue (https://www.tcl.tk/man/tcl8.6/TclCmd/file.htm#M39) but
for older versions we should probably stick with the existing pattern at
least on Windows.

-- 
Pat Thoyts                            http://www.patthoyts.tk/
PGP fingerprint 2C 6E 98 07 2C 59 C8 97  10 CE 11 E6 04 E0 B9 DD
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help